Skip to content

Site navigation

Crypto-assets

MiCA after July 2026: options for international crypto companies

The transitional arrangement has ended. What is left is a straightforward, and narrower, set of options.

The decision

Now that the transitional route has closed, what does a crypto business serving users in the Union actually need?

In short

The MiCA transitional arrangement for firms operating under national law before 30 December 2024 ran until 1 July 2026 at the latest, and Member States could end it sooner.910 International crypto companies serving EU users now need a crypto-asset service provider authorisation held by an EU-established entity, obtained directly or by acquiring an authorised provider.15 Token issuance is a separate question with a separate route.34

What the law requires

Who this decision is for, and who it is not for

This guide is for a business that provides crypto-asset services to users in the Union, or intends to, and now has to decide what it needs in order to keep doing so.

It is not for a firm whose assets are outside the framework altogether: assets that qualify as financial instruments, deposits or other instruments already regulated by Union financial services law fall outside it and are governed by those frameworks instead.2

It is not for a firm that already holds a Union authorisation as a credit institution, an investment firm or an electronic money institution and only wants to add specified crypto-asset services, because those entities may provide them on notification rather than through a separate authorisation.6

What the law requires

The transition has closed

MiCA allowed providers that were operating under national law before 30 December 2024 to continue for a limited period, which ran until 1 July 2026 at the latest. Member States could shorten that period or decline to apply it at all, so it ended earlier in some of them.910

The practical consequence is that a national registration obtained before MiCA is no longer a basis for serving EU users, and acquiring a firm that holds one is no longer a route in.910

What the law requires

The facts that change the answer

Which services the business actually provides, because the class of services sets the permanent minimum capital requirement that the own funds calculation starts from.8

Whether the business also issues a token, because offering an asset-referenced token to the public requires its own authorisation and an e-money token may be offered to the public only by an issuer authorised as a credit institution or as an electronic money institution.34

Whether the entity that will hold the authorisation is a legal person or other undertaking with a registered office in a Member State, with its place of effective management in the Union.15

Whether anything in the group already holds a Union authorisation that opens the notification route instead.6

Whether the firm is already a listed financial entity in another capacity, because operational resilience obligations attach to what a firm already is rather than to what it has applied for.11

What the law requires

What the authorisation actually requires

The applicant must be a legal person or other undertaking with a registered office in a Member State, with its place of effective management in the Union.15

Own funds must be at least the higher of the permanent minimum capital requirement for the class of services provided and one quarter of the fixed overheads of the preceding year. The class minimum on its own is not the requirement.8

Some firms that already hold a Union authorisation, including credit institutions, investment firms and electronic money institutions, can provide specified crypto-asset services on notification instead.6

What the law requires

Issuance is a separate route

Offering an asset-referenced token to the public requires its own authorisation. An e-money token may be offered to the public only by an issuer authorised as a credit institution or as an electronic money institution.34

A crypto-asset service provider authorisation carries neither, so a firm that both operates a platform and issues a token is answering two questions, not one.34

What the law requires

Three obligations that are usually treated as one

Authorisation to provide the services. It is granted to an established entity, and the own funds it carries are the higher of the class minimum and one quarter of the fixed overheads of the preceding year.158

Issuance, which is not obtained through a service provider authorisation and follows its own route.34

Operational resilience. Authorised crypto-asset service providers and issuers of asset-referenced tokens are among the financial entities listed in DORA, which has applied since its date of application.1112

Then reach, which is a fourth question and not part of the first three: an authorised provider may serve users in other Member States after its competent authority has communicated the cross-border notification.7

What the law requires

Where DORA fits

Authorised crypto-asset service providers and issuers of asset-referenced tokens are among the financial entities listed in DORA, so ICT risk management binds them directly once they are authorised.1112

Applying does not by itself bring a firm inside DORA, so before authorisation the obligation comes from the sectoral application requirements. A firm that already holds another authorisation making it a listed financial entity is a different case: DORA already binds it in that capacity.1113

RenIQ practitioner observation

Where this goes wrong

Shopping for a firm that still holds a registration from the old national rules. The route those registrations belonged to has closed, as the section above sets out with its sources, so what is being bought is the firm rather than the access.

Reading the class minimum as the capital requirement. The requirement stated above is the higher of two figures, one of which moves with the cost base, so a number fixed at the start of a plan is the wrong number by the time the plan is delivered.

Planning the platform and the token as one submission. They are two questions with two routes and two sets of evidence, and combining them tends to slow both.

Leaving operational resilience evidence until after authorisation, then finding that the group was inside those obligations all along in another capacity.

RenIQ practitioner observation

The decision to make next

Write down the exact list of services the business provides to users in the Union, and beside each one the entity that will provide it and where that entity is established. That list, rather than a country shortlist, decides the size and the shape of everything that follows.

Related regime guide: Crypto-assets

Primary sources for this page

13 citations, each to the article or section the statement rests on. The numbers beside a statement point to the citation behind it. Always confirm against the current official text.

  1. 1Article 3(1), points (16) and (17), definitions of crypto-asset service and crypto-asset service providerRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  2. 2Article 2, scope, including the exclusions in Article 2(3) and 2(4)Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  3. 3Article 16, authorisation to offer asset-referenced tokens to the public or seek their admission to tradingRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  4. 4Article 48, requirements for offering e-money tokens to the public or seeking their admission to tradingRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  5. 5Article 59, authorisation of crypto-asset service providersRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  6. 6Article 60, provision of crypto-asset services by certain already authorised financial entities on notificationRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  7. 7Article 65, cross-border provision of crypto-asset servicesRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  8. 8Article 67 and Annex IV, prudential requirements and permanent minimum capital requirements by class of crypto-asset servicesRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  9. 9Article 143(3) and Article 143(6), transitional measures for providers operating under national law before 30 December 2024Regulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  10. 10Article 149, entry into force and application datesRegulation (EU) 2023/1114 of the European Parliament and of the Council of 31 May 2023 on markets in crypto-assetsEuropean Parliament and Council of the European Union
  11. 11Article 2(1), the list of financial entities to which DORA applies, and Article 2(3), the entities excluded from itRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
  12. 12Article 64, entry into force and date of applicationRegulation (EU) 2022/2554 of the European Parliament and of the Council of 14 December 2022 on digital operational resilience for the financial sectorEuropean Parliament and Council of the European Union
  13. 13Article 5(1), the contents of an application for authorisation as a payment institution, including point (j), the security policy documentDirective (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal marketEuropean Parliament and Council of the European Union

Last updated 2026-08-26. 5 min read, calculated from 1006 words.

Talk through Regulatory Readiness Review

Your enquiry will record Regulatory Readiness Review as the engagement you are asking about. Tell RenIQ what you are building, where you want to operate and how far you have got, and a senior practitioner will come back on scope and on whether this is the right engagement for you.

Read what the engagement covers first: Regulatory Readiness Review.